PROOF · REQPROOF.COM
CH1 · CONTINUOUS CORRECTNESS AUDIT · STANDING INSTRUMENT

Confidence is a steady reading.

Proof is a standing audit of the promises your software makes. It re-runs on every change. When a promise breaks, you know first — as a signed finding with a reproducer, not a production surprise. The flat line is the product.

PROOF · CONTINUOUS CORRECTNESS AUDIT MODEL CCA-1 · SER. NO. 000123
CH1 · PROMISES HELD
● TRACKING
SWEEP 0.5 s/DIV · re-runs on every change
GAIN
SWEEP
TRIG
AUDIT ON
STANDING
CLASSES CLOSED · THIS SESSION
Live rendering of the audit loop: steady trace → finding → class closed → steady again. Findings shown are from the public jsonparser engagement register.
01

The reading: every promise, on one register

An audit you can't inspect is an opinion. Proof keeps a public register of every requirement it watches and every finding it raises — nothing summarized away, nothing quietly dropped. Each row carries its own evidence.

REGISTER · EXCERPT · JSONPARSER ENGAGEMENT STATUS AS AUDITED
IDClassSeverityStatusEvidenceSigned
F-001 panic on malformed input · 8 call sites HIGH CLOSED · SAME DAY reproducer + regression pin named auditor
F-004 Set() silent data loss HIGH CLOSED · FAMILY SWEPT reproducer + public postmortem named auditor
F-REP contract drift (representative example) MED CLOSED spec diff + pinned test named auditor
Rows F-001 and F-004 are real findings from the jsonparser engagement; the contract-drift row is a representative example of the class and is labeled as such on the live register. No entry ships without a reproducer, a status, and a named signature.

Severity

Every finding is graded, in the open. No burying a high behind a summary paragraph.

Status

Open, closed, or waived — with the who and the when. The register never forgets a row.

Evidence

A reproducer, a spec diff, a pinned test. Every claim on the register is re-runnable, not asserted.

Signature

A named person stands behind each verdict. Confidence you can attribute is confidence you can question.

02

A spike isn't a bug fixed. It's a class closed forever.

When the trace spikes, Proof doesn't patch the one site and move on. It formalizes the broken promise, sweeps the whole family, and pins a regression so the class cannot come back. From the jsonparser engagement:

123
Requirements approved
The library's actual promises, extracted from code and docs, formalized, and signed off one by one.
7
Findings raised
Each with severity, reproducer, and status on the public register. Not one summarized away.
8 → 0
Panic sites, closed same day
One panic class, found at 8 call sites. Fixed as a class, pinned as a class — same day.
Full disclosure · F-004

The one that got past us — and what a standing audit does about it

A silent data-loss defect in Set() escaped the initial audit — with 100% MC/DC coverage on the function. A downstream user caught it. We published the postmortem publicly, formalized the missing promise as a requirement, swept the entire defect family, and pinned it.

Coverage told a comfortable story; the register tells the true one. That class is now closed — permanently, with evidence. This is the difference between an audit that happened and an audit that's still running.
03

The corpus compounds, quarter by quarter

A one-time review depreciates the moment it's delivered. A standing audit appreciates: every approved requirement, every closed class, every pinned regression stays in the corpus and is re-verified on every change. The instrument never starts from zero.

Q1Q2Q3Q4
Verified corpus (illustrative) Finding raised ✓ class closed, stays closed

Nothing re-litigated

Approved requirements stay approved until deliberately retired. The audit spends its effort on what changed, not on re-proving last quarter.

Closed stays closed

Every closed class carries a pinned regression. A recurrence isn't a new bug — it's an alarm on a known promise, caught before merge.

Drift is a signal

When code moves away from its spec, the trace shows it as drift — visible on the register, not discovered in an incident review.

04

Agents and humans, held to one bar

Most teams now ship code written partly by AI — and most teams don't trust it. The industry's answer has been vibes: review harder, hope more. Proof's answer is an instrument: the same register, the same evidence bar, whether the diff came from a person or an agent.

Every requirement ships with agent-ready prompts, so your coding agents work inside the contract instead of around it. Every verdict carries a named human signature, so accountability never dissolves into "the model said so."

You don't have to trust the author. You trust the reading.

Trust gap · industry readings
Developers who distrust AI output accuracy46%
vs 33% who trust it — Stack Overflow Developer Survey
Teams using AI in the delivery loop90%
while roughly 30% trust its output — DORA research
What closes the gapevidence
a re-runnable register, not a reassurance
05

Put one component on the instrument

The engagement is deliberately small and sharp: one component, fixed fee, about four weeks to a signed register — then the audit keeps running as your code keeps changing.

T+0

Scope one component

Pick the code whose failures cost you sleep — a parser, a billing path, a sync engine. Fixed fee, agreed up front.

W1–2

Extract & approve the promises

We formalize what the component actually guarantees. You approve each requirement — nothing enters the corpus unsigned.

W3–4

Verify, find, close

Findings land on the register with severity, reproducer, and status. Classes get closed and pinned, not patched.

Then it stands

The audit re-runs on every change. The steady reading — and the first word when it spikes — is what you're buying.

LOG ENTRY · SCOPING REQUEST — — —
Email is enough to start. We reply with scope and a fixed quote — no call required.
CCA-1 · SCOPING CHANNEL NO RETAINER UNTIL SCOPE IS SIGNED